Getting Data In

Nullque setup help

Antioch
Path Finder

basically I am attempting to filter wmi eventlogs before they are indexed by the splunk server, I found a topic about this but I had a few more basic questions. I'm looking at the steps for setting up forwarding to the nullque here: http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Routeandfilterdatad but im not quite understanding the directions. First step is to edit props.conf, but when I look in my directory I have multiple props.conf files. Do I need to edit all of them? If not what is the path of the file I should be editing? I found the props.conf under splunkdir/etc/system/default, is this the right one? if so this file indicated it should be placed in the etc/system/local file, should I just be copying and pasting the whole file? or just the relevant sections? same goes for the transforms.conf, which one is the correct one? thanks for the help everyone

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

No you do not need to edit all of the files. Please look at this link below in the docs for file precedence. In most cases you'll create a new file under /system/local for props.conf and transforms.conf but it really depends. As long as you are not changing the default directory you are ok, since that is really for the base system or application. Changes within 'local' won't be overridden when you upgrade versions of Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Wheretofindtheconfigurationfiles

softunlockiphon
New Member

good idea for all very nice hehehehe

0 Karma

Antioch
Path Finder

Thank you, the routing setup page should have a link back to this doc for reference.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...